diff options
| -rw-r--r-- | lib/libsys/fcntl.2 | 9 | ||||
| -rw-r--r-- | sys/kern/vfs_syscalls.c | 9 |
2 files changed, 17 insertions, 1 deletions
diff --git a/lib/libsys/fcntl.2 b/lib/libsys/fcntl.2 index b919e1b8674b..123dd5543ab2 100644 --- a/lib/libsys/fcntl.2 +++ b/lib/libsys/fcntl.2 @@ -25,7 +25,7 @@ .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF .\" SUCH DAMAGE. .\" -.Dd June 24, 2025 +.Dd September 22, 2026 .Dt FCNTL 2 .Os .Sh NAME @@ -173,6 +173,13 @@ and similar operations, and opening a directory with .Xr openat 2 where the directory descriptor has the flag set causes the new directory descriptor to also have the flag set. +A file descriptor with the +.Dv FD_RESOLVE_BENEATH +set cannot be used as either the source or target descriptor in +.Xr renameat 2 +or +.Xr renameat2 2 +system calls. .El .It Dv F_SETFD Set flags associated with diff --git a/sys/kern/vfs_syscalls.c b/sys/kern/vfs_syscalls.c index 8096ffc7be6c..5bc8dd5c5f91 100644 --- a/sys/kern/vfs_syscalls.c +++ b/sys/kern/vfs_syscalls.c @@ -3869,6 +3869,15 @@ again: error = EEXIST; goto out; } + if (fvp->v_type == VDIR && + ((fromnd.ni_resflags | tond.ni_resflags) & NIRES_BENEATH) != 0) { + /* + * We must not rename a directory relative to FD_RESOLVE_BENEATH + * descriptors. + */ + error = ENOTCAPABLE; + goto out; + } if (exchange) { if (tvp == NULL) { error = ENOENT; |
